<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: HD Moore&#8217;s Company BreakingPoint Suffers DNS Attack</title>
	<atom:link href="http://www.darknet.org.uk/2008/08/hd-moores-company-breakingpoint-suffers-dns-attack/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2008/08/hd-moores-company-breakingpoint-suffers-dns-attack/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Sun, 08 Nov 2009 07:15:43 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Morgan Storey</title>
		<link>http://www.darknet.org.uk/2008/08/hd-moores-company-breakingpoint-suffers-dns-attack/#comment-124521</link>
		<dc:creator>Morgan Storey</dc:creator>
		<pubDate>Thu, 14 Aug 2008 05:21:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=962#comment-124521</guid>
		<description>so I am the first to admit I have gaps in my knowledge. 
Never heard of DNSSEC, now I that have listened to the Blackhat talk I have heard about it. I had a quick look at wikipedia and the official site and it is interesting. Of course windows servers only support it as a secondary, also the glaring-hole of non NSEC3 servers allowing enumeration of sites is just plain silly. Seriously just hash The users request domain &quot;Not Found&quot; and add it to the RFC, done.
I think it should include the option for encrypting replies, may as well, could be useful for higher secure organisations.</description>
		<content:encoded><![CDATA[<p>so I am the first to admit I have gaps in my knowledge.<br />
Never heard of DNSSEC, now I that have listened to the Blackhat talk I have heard about it. I had a quick look at wikipedia and the official site and it is interesting. Of course windows servers only support it as a secondary, also the glaring-hole of non NSEC3 servers allowing enumeration of sites is just plain silly. Seriously just hash The users request domain &#8220;Not Found&#8221; and add it to the RFC, done.<br />
I think it should include the option for encrypting replies, may as well, could be useful for higher secure organisations.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Morgan Storey</title>
		<link>http://www.darknet.org.uk/2008/08/hd-moores-company-breakingpoint-suffers-dns-attack/#comment-124517</link>
		<dc:creator>Morgan Storey</dc:creator>
		<pubDate>Thu, 14 Aug 2008 02:34:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=962#comment-124517</guid>
		<description>@Brill: Yeah NAT negates the patch in most parts as the NAT doesn&#039;t randomise the port. Dan even said the patch doesn&#039;t 100% fix it, just makes it harder to guess the next port. So it was only a matter of time before someone &quot;brute forced&quot; the port. Scary that they did it this fast, but really they did it over Gige in 10 hours. So most DNS servers that are doing resolves for clients, are probably not even on 20mbs of bandwidth, and latency 10+ times that of ethernet. So you could say it would take 10+ times longer to do this over the internet, so 100hours. Someone will hopefully notice at around hour 20...
I blogged about this, I think we need to have signed or ssl DNS forwarding and root servers, it wouldn&#039;t be that hard to implement.</description>
		<content:encoded><![CDATA[<p>@Brill: Yeah NAT negates the patch in most parts as the NAT doesn&#8217;t randomise the port. Dan even said the patch doesn&#8217;t 100% fix it, just makes it harder to guess the next port. So it was only a matter of time before someone &#8220;brute forced&#8221; the port. Scary that they did it this fast, but really they did it over Gige in 10 hours. So most DNS servers that are doing resolves for clients, are probably not even on 20mbs of bandwidth, and latency 10+ times that of ethernet. So you could say it would take 10+ times longer to do this over the internet, so 100hours. Someone will hopefully notice at around hour 20&#8230;<br />
I blogged about this, I think we need to have signed or ssl DNS forwarding and root servers, it wouldn&#8217;t be that hard to implement.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brill</title>
		<link>http://www.darknet.org.uk/2008/08/hd-moores-company-breakingpoint-suffers-dns-attack/#comment-124476</link>
		<dc:creator>Brill</dc:creator>
		<pubDate>Tue, 12 Aug 2008 22:06:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=962#comment-124476</guid>
		<description>Here you have some recent news!! it seems that the patch for this security hole doesn&#039;t solve the vulnerability!!.... there have been some sucessfull test on servers already patched and not with just a proof o concept but with a  whole functional exploit.
Here the overall comment from NY Times
http://www.nytimes.com/2008/08/09/technology/09flaw.html
And here the original comment in the post of the Russian physicist who discover it.
http://tservice.net.ru/~s0mbre/blog/devel/networking/dns/2008_08_08.html</description>
		<content:encoded><![CDATA[<p>Here you have some recent news!! it seems that the patch for this security hole doesn&#8217;t solve the vulnerability!!&#8230;. there have been some sucessfull test on servers already patched and not with just a proof o concept but with a  whole functional exploit.<br />
Here the overall comment from NY Times<br />
<a href="http://www.nytimes.com/2008/08/09/technology/09flaw.html" rel="nofollow">http://www.nytimes.com/2008/08/09/technology/09flaw.html</a><br />
And here the original comment in the post of the Russian physicist who discover it.<br />
<a href="http://tservice.net.ru/~s0mbre/blog/devel/networking/dns/2008_08_08.html" rel="nofollow">http://tservice.net.ru/~s0mbre/blog/devel/networking/dns/2008_08_08.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brill</title>
		<link>http://www.darknet.org.uk/2008/08/hd-moores-company-breakingpoint-suffers-dns-attack/#comment-124475</link>
		<dc:creator>Brill</dc:creator>
		<pubDate>Tue, 12 Aug 2008 22:03:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=962#comment-124475</guid>
		<description>@Morgan, Thanks for the link!!... Linking it with the presentation it will be the nearest I will have to be at any Black Hat presentation.

I will try to save some time to hear it with calm...

This one received a lot of publicity but, Does anyone of the lucky guys that could attend recomend any other presentation?</description>
		<content:encoded><![CDATA[<p>@Morgan, Thanks for the link!!&#8230; Linking it with the presentation it will be the nearest I will have to be at any Black Hat presentation.</p>
<p>I will try to save some time to hear it with calm&#8230;</p>
<p>This one received a lot of publicity but, Does anyone of the lucky guys that could attend recomend any other presentation?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: lyz</title>
		<link>http://www.darknet.org.uk/2008/08/hd-moores-company-breakingpoint-suffers-dns-attack/#comment-124468</link>
		<dc:creator>lyz</dc:creator>
		<pubDate>Tue, 12 Aug 2008 15:49:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=962#comment-124468</guid>
		<description>weehee.. This post is just in time for my re-echo of the Hackacon 2008 event I&#039;ve attended here in our country.</description>
		<content:encoded><![CDATA[<p>weehee.. This post is just in time for my re-echo of the Hackacon 2008 event I&#8217;ve attended here in our country.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Darknet</title>
		<link>http://www.darknet.org.uk/2008/08/hd-moores-company-breakingpoint-suffers-dns-attack/#comment-124421</link>
		<dc:creator>Darknet</dc:creator>
		<pubDate>Sat, 09 Aug 2008 08:51:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=962#comment-124421</guid>
		<description>Just relax, nothing disappears, posting the same thing 10 times then I have to go through each one and see which ones are the same and which ones are different and which one I should post and which I should delete - now that&#039;s annoying. Everything will get through, just wait I&#039;m on holiday.</description>
		<content:encoded><![CDATA[<p>Just relax, nothing disappears, posting the same thing 10 times then I have to go through each one and see which ones are the same and which ones are different and which one I should post and which I should delete &#8211; now that&#8217;s annoying. Everything will get through, just wait I&#8217;m on holiday.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Morgan Storey</title>
		<link>http://www.darknet.org.uk/2008/08/hd-moores-company-breakingpoint-suffers-dns-attack/#comment-124387</link>
		<dc:creator>Morgan Storey</dc:creator>
		<pubDate>Thu, 07 Aug 2008 11:30:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=962#comment-124387</guid>
		<description>@Brill: yeah I found a link to the MP3, I just downloaded it from here http://blackhat.com/html/webinars/kaminsky-DNS.html

It is pretty long, I&#039;ll listen to it at lunch tomorrow. I should have listened to the webcast live.</description>
		<content:encoded><![CDATA[<p>@Brill: yeah I found a link to the MP3, I just downloaded it from here <a href="http://blackhat.com/html/webinars/kaminsky-DNS.html" rel="nofollow">http://blackhat.com/html/webinars/kaminsky-DNS.html</a></p>
<p>It is pretty long, I&#8217;ll listen to it at lunch tomorrow. I should have listened to the webcast live.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brill</title>
		<link>http://www.darknet.org.uk/2008/08/hd-moores-company-breakingpoint-suffers-dns-attack/#comment-124385</link>
		<dc:creator>Brill</dc:creator>
		<pubDate>Thu, 07 Aug 2008 08:42:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=962#comment-124385</guid>
		<description>Today was the lecture of Dan Kaminsky at Black Hat, altough his presentation is not available yet at Black Hat site, you can find it in Dan&#039;s site http://www.doxpara.com/DMK_BO2K8.ppt
Has anyone attended who can provide some feedback?.</description>
		<content:encoded><![CDATA[<p>Today was the lecture of Dan Kaminsky at Black Hat, altough his presentation is not available yet at Black Hat site, you can find it in Dan&#8217;s site <a href="http://www.doxpara.com/DMK_BO2K8.ppt" rel="nofollow">http://www.doxpara.com/DMK_BO2K8.ppt</a><br />
Has anyone attended who can provide some feedback?.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: zupakomputer</title>
		<link>http://www.darknet.org.uk/2008/08/hd-moores-company-breakingpoint-suffers-dns-attack/#comment-124376</link>
		<dc:creator>zupakomputer</dc:creator>
		<pubDate>Wed, 06 Aug 2008 17:44:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=962#comment-124376</guid>
		<description>I may have a dewy-eyed view of Malaysia but it must be hard picking a better holiday destination when you&#039;re in a tropical paradise already! Iceland perhaps, something a bit different.....or it works out better cause you don&#039;t have to travel at all, just holiday in the same country.

This DNS thing - what if you tried to complain to your ISP that their caching was poisoned, but their own website was redirecting to a fake ad site too......</description>
		<content:encoded><![CDATA[<p>I may have a dewy-eyed view of Malaysia but it must be hard picking a better holiday destination when you&#8217;re in a tropical paradise already! Iceland perhaps, something a bit different&#8230;..or it works out better cause you don&#8217;t have to travel at all, just holiday in the same country.</p>
<p>This DNS thing &#8211; what if you tried to complain to your ISP that their caching was poisoned, but their own website was redirecting to a fake ad site too&#8230;&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CG</title>
		<link>http://www.darknet.org.uk/2008/08/hd-moores-company-breakingpoint-suffers-dns-attack/#comment-124375</link>
		<dc:creator>CG</dc:creator>
		<pubDate>Wed, 06 Aug 2008 15:47:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=962#comment-124375</guid>
		<description>old news and over hyped

&quot;It seems more of a problem with the ISP than BreakingPoint itself&quot;

...tisk tisk for your post title</description>
		<content:encoded><![CDATA[<p>old news and over hyped</p>
<p>&#8220;It seems more of a problem with the ISP than BreakingPoint itself&#8221;</p>
<p>&#8230;tisk tisk for your post title</p>
]]></content:encoded>
	</item>
</channel>
</rss>
